Fiche vulnérabilité
CVE-2022-2906 : faille élevée ISC BIND9 (CVSS 7.5)
Description
An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 21 sept. 2022
- Dernière mise à jour
- 28 mai 2025
Produits concernés
- ISC BIND9
Correctif et mesures
Upgrade to the patched release most closely related to your current version of BIND: BIND 9.18.7 or BIND 9.19.5.